QuickJS Ng is a JavaScript engine implementation that, despite a narrow product footprint, has gained prominence in embedded and specialized runtime environments where lightweight script execution is required. The vendor's vulnerability disclosures cluster around a single core product and reflect the parsing and execution demands inherent to a dynamic language interpreter. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quickjs Ng over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-0821CRITICAL A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulatio | Jan 10, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-1145HIGH A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation caus | Jan 19, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-1144HIGH A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation result | Jan 19, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-0822HIGH A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort of the file quickjs.c. The manipulation leads to heap-based b | Jan 10, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-46688HIGH quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected. | Apr 27, 2025 | 8.4 | 22 | NO | NO |
CVE-2025-46687HIGH quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected. | Apr 27, 2025 | 7.8 | 22 | NO | NO |
CVE-2024-13903HIGH A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulnerability is the function JS_GetRuntime of the file quickjs.c | Mar 21, 2025 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quickjs Ng.
Media articles that mention a CVE ID that affects a product developed by Quickjs Ng — matched by CVE ID, not by vendor name.